CVE-2026-13159: Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Real Estate Papi (WordPress theme)to a version that resolves this vulnerability.Fixed in 1.0.5
Event History
Frequently Asked Questions
Which users can trigger the vulnerable action?
Any authenticated WordPress user, including a subscriber-level account, can invoke the affected AJAX action to install the fixed set of companion plugins from the WordPress.org repository.
When will the installed plugins also be activated?
Activation occurs when the vulnerable request executes in the session of a user who has permission to activate plugins. The issue otherwise allows installation of the fixed companion-plugin set.